DefSec Wire
  • Home
  • Defense
    • Army
    • Marine Corps
    • Navy
    • Air Force
    • Space Force
  • Air
  • Land
  • Sea
  • Space
  • Cyber
  • Industry
  • Security
No Result
View All Result
  • United States flag United States
  • Australia flag Australia
  • United Kingdom flag United Kingdom
  • Europe flag Europe
  • New Zealand flag New Zealand
  • Canada flag Canada
DefSec Wire
  • Home
  • Defense
    • Army
    • Marine Corps
    • Navy
    • Air Force
    • Space Force
  • Air
  • Land
  • Sea
  • Space
  • Cyber
  • Industry
  • Security
No Result
View All Result
DefSec Wire
No Result
View All Result
Home Security

NSA and CISA co-author updated software bill of materials (SBOM)

Lila Carvello by Lila Carvello
July 29 2026
in Security
0
NSA and CISA co-author updated software bill of materials (SBOM)
172
SHARES
2.5k
VIEWS
Share on LinkedInFacebookTwitter

FORT MEADE, Md. — The National Security Agency and the Cybersecurity and Infrastructure Security Agency on Wednesday published updated baseline requirements for software bills of materials, aiming to sharpen the way organizations assess supply chain risk across everything from open-source packages to artificial intelligence systems and SaaS.

You Might Also Like

U.S. Forces Conduct Strike Targeting al-Shabaab

U.S. approves military sale to Norway of 155mm high explosive (HE) M795 projectiles

The new Cybersecurity Information Sheet, “2026 Minimum Elements for a Software Bill of Materials (SBOM),” refreshes the government’s 2021 guidance from the National Telecommunications and Information Administration and folds in technical advances that have reshaped how software is built and deployed. The document is available at: https://media.defense.gov/2026/Jul/29/2003971159/-1/-1/1/CSI_2026_cisa_sbom_minimum_elements_508c.PDF

Among the notable additions are:
– SBOM Author Signature, to authenticate who generated the SBOM
– SBOM Version, to track iterations of the bill of materials itself
– Component Hash Value, to provide cryptographic integrity for listed components

The update also tightens expectations for several existing fields, including clearer definitions around the SBOM Author, more precise Component Identifiers, and better articulation of Coverage to describe how thoroughly a product’s components are represented. Smaller adjustments address data quality and alignment with current tooling and practices, such as Timestamp conventions, how to represent Component Dependency Relationships, and expectations for Distribution and Delivery of SBOMs.

CISA and NSA position the revised elements as the floor for transparency across software types, explicitly encompassing open-source, AI-enabled software, and cloud-delivered services. The guidance outlines how producers should generate SBOMs and how customers should request and use them, while noting that more complex systems may warrant additional fields beyond the minimum.

SBOMs function as an inventory of the components inside software, capturing how those parts relate to one another so that machines can parse and act on the data quickly. By standardizing a common set of fields—and strengthening trust signals like signatures and hashes—the agencies aim to make it easier for organizations to automate vulnerability mapping, dependency analysis, and response workflows at scale.

The push to normalize SBOM practices has accelerated since high-profile supply chain compromises and widespread component vulnerabilities underscored the need for visibility into upstream code. A 2021 executive order on cybersecurity directed federal agencies to advance SBOM adoption in procurement and risk management, and industry tooling has matured around formats like SPDX and CycloneDX to support generation and ingestion. The latest update is intended to keep pace with those developments and with the growing volume of third-party and open-source components in modern applications.

In practical terms, the changes could make it simpler for buyers to compare SBOMs across vendors, verify provenance, and tie listed components to external data sources, such as vulnerability feeds and exploit intelligence. For suppliers, clearer expectations reduce ambiguity in what must be provided and how often SBOMs should be refreshed, especially as software is continuously delivered.

The agencies emphasize that as new use cases appear—particularly in AI pipelines and cloud-native environments—the minimum elements will continue to evolve. For now, they urge organizations to treat SBOMs as living artifacts that feed directly into routine security decisions, from patch prioritization to incident response.

The full report and additional technical guidance are available through NSA and CISA’s public libraries:
– Report: https://media.defense.gov/2026/Jul/29/2003971159/-1/-1/1/CSI_2026_cisa_sbom_minimum_elements_508c.PDF
– NSA cybersecurity advisories: https://www.nsa.gov/Cybersecurity/Cybersecurity-Advisories-Guidance/

Tags: Cybersecurity and Infrastructure Security AgencyNational Security Agency
Previous Post

DLA launches new weapons support command to boost global readiness

Next Post

CISA and partners unveil updated software bill of materials resource to improve transparency, security and risk-informed decision-making

Lila Carvello

Lila Carvello

Lila Carvello is a journalist reporting on security and intelligence in the United States and abroad. She focuses on global defence, espionage and national security developments shaping international relations.

Related News

U.S. Forces Conduct Strike Targeting al-Shabaab

by Stephanie Clarke
August 8 2026
0

U.S. Africa Command (AFRICOM) executed an airstrike against al-Shabaab on August 7, 2026, in coordination with the Federal Government of...

Sweden – M142 High Mobility Artillery Rocket Systems

U.S. approves military sale to Norway of 155mm high explosive (HE) M795 projectiles

by Sienna Parker
August 5 2026
0

The U.S. State Department has approved a potential $270 million sale of 155mm M795 high-explosive artillery projectiles and related support...

USS George Washington arrives in Da Nang, underscoring enduring U.S.-Vietnam ties

USS George Washington docks in Da Nang, underscoring enduring U.S.-Vietnam ties

by Stephanie Clarke
August 5 2026
0

Da Nang, Vietnam — The Nimitz-class aircraft carrier USS George Washington (CVN 73), flagship of Carrier Strike Group (CSG) 5,...

Sweden – M142 High Mobility Artillery Rocket Systems

U.S. approves military sale to Austria of UH-60M Black Hawk helicopters

by Sienna Parker
August 5 2026
0

The U.S. State Department has approved a potential $1.5 billion Foreign Military Sale to Austria for 12 UH-60M Black Hawk...

Next Post

CISA and partners unveil updated software bill of materials resource to improve transparency, security and risk-informed decision-making

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending News

Air Force overhauls officer developmental education

Air Force unveils FY26 aviation bonus program

April 8 2026
T-38 Talon operations paused

T-38 Talon operations paused

May 19 2026
Air Force rolls out myBodyComp, reiterates July 31 deadline for waist-to-height ratio checks

Air Force rolls out myBodyComp, reiterates July 31 deadline for waist-to-height ratio checks

July 23 2026

About

DefSec Wire reports on the news that matters in the Defense, Security and Intelligence industries across the United States and the world.

Our Network

  • DefSec Wire
  • DefSec Wire Australia
  • DefSec Wire UK
  • DefSec Wire Europe
  • DefSec Wire New Zealand
  • DefSec Wire Canada

DefSec Wire

  • About Us
  • Advertise
  • Contact
  • Our Team
  • Join Our Team
  • Contribute to DefSec Wire
  • Ethical Tech

Legal

  • Terms of Service
  • Privacy Policy

Categories

  • Air
  • Air Force
  • Army
  • Cyber
  • Defense
  • Foreign Military Sale
  • Industry
  • Land
  • Logistics
  • Marine Corps
  • Military Operations
  • Navy
  • Research & Development
  • Sea
  • Security
  • Space
  • Space Force

Popular Tags

7th Fleet Air National Guard Arleigh Burke-class Boeing Cybersecurity and Infrastructure Security Agency Defense Advanced Research Projects Agency Defense Counterintelligence and Security Agency Defense Logistics Agency Defense Security Cooperation Agency Department of Defense Department of State Department of the Air Force DLA Disposition Services DLA Energy DLA Weapons Support F-35 Foreign Military Sale HII Indo-Pacific Ken Wilsbach L3Harris Lockheed Martin Mark Simerly National Security Agency NATO Pete Hegseth Raytheon RTX Somalia Troy Meink U.S. Africa Command U.S. Air Force U.S. Army U.S. Central Command U.S. Marine Corps U.S. Military Operation U.S. Navy U.S. Southern Command U.S. Space Command U.S. Space Force USAFRICOM USCENTCOM USINDOPACOM USSOUTHCOM USSTRATCOM

Recent Posts

  • U.S. Forces Conduct Strike Targeting al-Shabaab
  • Office of Strategic Capital signs $150 million conditional loan commitment with Niron Magnetics to scale domestic rare earth-free magnet production
  • War Department announces $85.5 million agreement with Strategic Bauxite USA to secure critical refractory-grade bauxite supply chain
  • Office of Strategic Capital signs $1.4 billion conditional loan commitment with Sila Nanotechnologies to boost US battery production
  • Office of Strategic Capital signs $400 million conditional loan commitment with Sunrise Energy Metals Limited to expand scandium mining
  • After Hill, Utah go-live, DLA Distribution completes global warehouse overhaul and turns to stabilization
  • Navy relieves commanding officer of Navy Medicine Readiness and Training Command Lemoore
  • Three nations, one force: allied integration shrinks the operational world

© 2026 DefSec Wire – part of the DefSec Wire Group.

No Result
View All Result
  • Home
  • Defense
    • Army
    • Marine Corps
    • Navy
    • Air Force
    • Space Force
  • Air
  • Land
  • Sea
  • Space
  • Cyber
  • Industry
  • Security

© 2026 DefSec Wire – part of the DefSec Wire Group.